Layer 6: Human-Centric Cyber Defense—Security Awareness & Training
摘要
Human error remains a critical vulnerability in cybersecurity, particularly in small organizations with limited resources. This chapter proposes a redesigned ADDIE model for Human-Centric Cyber Defense Training, integrating open-source tools and advanced technologies to provide a cost-effective yet robust awareness framework. The methodology combined literature review, expert consultation, and pilot deployments of GoPhish, Phishing Frenzy, King Phisher, and OWASP Security Shepherd across three universities, each involving 100 employees. Results showed that while phishing simulations significantly improved awareness, notable gaps persisted, with varying click and report rates across institutions. To address these shortcomings, the proposed framework incorporates AI-driven personalization, immersive VR/MR/XR simulations, gamified training, biometric monitoring, blockchain-secured certification, and continuous microlearning. By emphasizing adaptability and affordability, the model enables SMEs to strengthen their human-centric defense without reliance on costly proprietary systems. The findings demonstrate that integrating open-source simulation tools with advanced, behavior-focused methodologies creates a scalable and practical pathway for reducing human-related cyber risks.